How Zapret's Game Filter Mode Bypasses DPI for Games and UDP Applications
Zapret's Game Filter mode captures all TCP and UDP traffic on high-numbered ports (1024-65535) using WinDivert, forcing game traffic through a user-space filter that circumvents Deep Packet Inspection (DPI) by intercepting packets before the Windows networking stack processes them.
The Flowseal/zapret-discord-youtube repository provides a Windows implementation of the zapret DPI bypass tool, featuring a specialized Game Filter configuration designed specifically for UDP-heavy gaming applications. This mode enables the winws.exe binary to intercept dynamic high-port connections that traditional DPI systems often fail to inspect, effectively creating a transparent tunnel for game traffic.
What Is Game Filter Mode?
Game Filter is a traffic capture configuration managed through service.bat that directs the bypass engine to handle all connections on ephemeral ports. When activated, the script creates a persistence flag at utils\game_filter.enabled containing one of three values: all, tcp, or udp. These values determine whether the service intercepts both protocols or isolates a specific transport layer, with the configuration persisting across system restarts until explicitly disabled.
How Game Filter Bypasses DPI
The bypass mechanism operates through three coordinated stages that redirect packets around network inspection points.
Port Range Selection
The activation logic resides in service.bat within the Game Switch block (lines 71-83 and 91-119). When a user selects Game Filter from the interactive menu, the script evaluates the choice and sets environment variables accordingly:
- Mode
all: SetsGameFilter=1024-65535for both TCP and UDP - Mode
tcp: SetsGameFilterTCP=1024-65535for TCP only - Mode
udp: SetsGameFilterUDP=1024-65535for UDP only
These variables are stored in utils\game_filter.enabled and parsed during service initialization to determine which port ranges WinDivert should capture.
Argument Injection
During service installation (service_install section, lines 302-308), service.bat performs placeholder substitution on the strategy file. The script replaces %%GameFilter%%, %%GameFilterTCP%%, and %%GameFilterUDP%% tokens with the numeric ranges defined in the previous stage. The resulting arguments are appended to the service creation command:
sc create zapret binPath= "\"%BIN_PATH%winws.exe\" !ARGS!" start= auto
This injection occurs at lines 49-52 of service.bat, ensuring the WinDivert driver captures the specified port ranges immediately upon service startup.
WinDivert Packet Interception
The winws.exe binary utilizes the WinDivert driver to operate at the Windows filtering platform layer, intercepting raw packets before they reach the standard networking stack. By supplying the high-port range arguments (1024-65535), the tool captures all traffic on dynamic ports commonly used by online games. Because DPI implementations typically monitor standard ports (80, 443) and struggle with high-volume UDP streams, diverting these packets through user-space processing effectively removes them from the ISP's inspection path.
Enabling Game Filter Mode
Activation requires running service.bat and navigating the interactive menu system defined at lines 94-98, with the game_switch routine handling input at lines 443-473.
- Execute
service.batand select 4. Game Filter - Choose the desired mode:
- 0: Disable Game Filter
- 1: Enable TCP and UDP (full coverage)
- 2: Enable TCP only
- 3: Enable UDP only (optimal for most games)
- Confirm the selection to write the flag to
utils\game_filter.enabled - Restart the Zapret service to apply the new port filters
Technical Configuration Examples
Manual configuration follows the same variable substitution pattern used by the automated installer. Setting the full Game Filter mode requires defining the environment variables before service creation:
:: Enable full TCP and UDP filtering
set "GameFilter=1024-65535"
set "GameFilterTCP=1024-65535"
set "GameFilterUDP=1024-65535"
:: Build argument string with placeholders replaced
set "ARGS=--port=%GameFilter% --tcp-port=%GameFilterTCP% --udp-port=%GameFilterUDP%"
:: Create and start the service
sc create zapret binPath= "\"%~dp0bin\winws.exe\" %ARGS%" start= auto
sc start zapret
The flag file contents correspond directly to menu selections:
:: TCP and UDP mode
all
:: UDP only mode
udp
:: TCP only mode
tcp
Summary
- Game Filter redirects high-port traffic (1024-65535) through WinDivert by configuring
winws.exewith dynamic port-range arguments injected viaservice.bat. - The mode persists configurations in
utils\game_filter.enabled, supporting three operational states: TCP only, UDP only, or both protocols simultaneously. - Bypass occurs at the packet level: WinDivert intercepts raw traffic before Windows processes it, preventing DPI systems from analyzing game data flows.
- Most effective for UDP-based games that utilize dynamic high ports rather than standard HTTP/HTTPS channels.
Frequently Asked Questions
What port ranges does Game Filter mode affect?
Game Filter captures all traffic on ports 1024 through 65535, covering the entire ephemeral port range used by modern multiplayer games and peer-to-peer applications. Standard service ports (0-1023) remain unaffected, ensuring system stability while gaming traffic receives DPI bypass treatment.
Why is Game Filter more effective for games than standard bypass modes?
Traditional DPI concentrates inspection efforts on well-known ports like 80 and 443, while many games utilize dynamic high ports and UDP protocol for real-time communication. Game Filter specifically targets these overlooked traffic patterns by forcing WinDivert to intercept packets on the exact ports games actually use, creating a tunnel that circumvents shallow packet inspection techniques.
How do I completely disable Game Filter after enabling it?
Navigate to service.bat and select 4. Game Filter, then choose option 0 to disable. This removes the port range arguments from the service configuration during the next restart. Alternatively, delete the utils\game_filter.enabled flag file manually and restart the Zapret service to return to standard filtering behavior.
Does Game Filter impact system performance or other applications?
Because Game Filter captures traffic across the entire high-port spectrum (1024-65535), it may intercept non-gaming applications that utilize these ports, such as voice chat software or torrent clients. The performance impact remains minimal due to WinDivert's kernel-level efficiency, but users may notice the bypass affecting traffic characteristics for any application using high-numbered ports while the mode is active.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →